An article on the relative security and insecurity of websites and banks
Why is it that websites deem a 6 character all lower case password to be "very weak" when there's 306million+ possibilities. Yet a 4 digit PIN (9999 possibilities) is secure enough for banks?
The website one is almost 31,000 times more secure yet is deemed "weak". Surely a rule for websites that if the incorrect password is used a certain number of times the account is locked would be sufficient to make the weak password 31,000 times stronger than the bank's security.
We have to be practical about this. In reality, any rules around requiring a password to have upper and lower case letter and special characters such as $,% etc simply make it much more likely people will write the passwords down. Just because this makes it the person's problem rather than the website's is no excuse - the overall security of the account is the issue, including the likelyhood that the account will be broken into because the password was so complicated it, together with the dozons of other passwords from other sites, all had to be written down somewhere because it was too much to remember.
Can we please have simpler password rules for websites and some way of having one strong security mechanism which ties them all together?
Craig
By Craig Cockburn, IT Professional from Scotland. Digital Transformation, Agile Management, Politics and Social change
Subscribe to:
Post Comments (Atom)
Popular Posts
-
My article about Dyson's breakdown problems made the front page of reddit and hopefully this article on Bosch will do so too because m...
-
The UK Government Digital Service (GDS) has just had a reboot . However will it be value for money and deliver its objectives? Will th...
-
I've been having a busy time over on the Cambrian House site lately. Check out my profile and the full set of awards I completed last ...
-
An article on how Agile can sit alongside PRINCE2 and where DSDM Atern fits in. In 2007, I put "used an Agile/PRINCE2 development str...
-
Every time I go to the post office there's a queue. No matter how much they try and keep the queue length down, inevitably you get stuck...
-
How Aer Lingus is cheaper than Ryanair. This'll annoy Michael O'Leary. This is my weekly flight, so these are real figures based on...
-
Argos (a top 5 e-commerce site in the UK ) reports on its website when you go to buy something: Remember, you don't need to register t...
-
It has always surprised me that in the US, where holidays are valued and children get about 6 weeks more annual holiday than the UK, that ad...
-
As a contractor living away from home Mon-Thu in hotels, I am now experiencing the joys and delights of living in hotel rooms for up to 200 ...
-
I had the unpleasant experience of trying to uninstall McAfee SecurityCenter today. I needed to install it to test a website that was incorr...

No comments:
Post a comment